PKI, Cryptography and Zero Trust Architect

Iron Bow Technologies
Herndon, VA, United States
8 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Federal Information Processing Standards (FIPS) Information Systems Security Architecture Professional Public Key Infrastructure Zero Trust Network Access Sherwood Applied Business Security Architecture Togaf

Job description

  • Develop enterprise PKI, KMS, cryptographic, and HSM architecture supporting VA operational and cybersecurity requirements.
  • Architect HSM-backed roots of trust and integration with enterprise Certificate Authorities and KMS platforms.
  • Design Zero Trust cryptographic controls aligned with NIST SP 800-207 and VA Critical Security Controls.
  • Integrate HSM architecture with enterprise ICAM services, machine identity, authentication, authorization, and least-privilege controls.
  • Design hybrid classical/post-quantum cryptographic architectures supporting phased PQC adoption.
  • Architect parallel PQC/hybrid CA hierarchies to enable transition without disruption to production PKI.
  • Develop approaches for cross-certification, new trust-anchor distribution, certificate issuance/validation, revocation, OCSP, and enrollment.
  • Support development of the Zero Trust Implementation Plan and define measurable Zero Trust maturity targets.
  • Design management-plane segmentation, mutually authenticated communications, machine identity, privileged-access controls, quorum control, and tamper-evident audit capabilities.
  • Support development and maintenance of the Crypto Agility Plan and Cryptographic Bill of Materials.
  • Evaluate architectural impacts of evolving NIST, IETF, CNSA 2.0, and Federal cryptographic standards.

Requirements

The position requires demonstrated experience designing and operating enterprise PKI and key-management architectures and working knowledge of FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). The candidate should be able to demonstrate prior work involving hybrid classical/PQC architectures and Zero Trust designs consistent with NIST SP 800-207. Primarily remote. Limited travel to customer facility., * Demonstrated enterprise PKI architecture and operations experience.

  • Demonstrated enterprise KMS and HSM architecture experience.
  • Strong understanding of Zero Trust architecture and NIST SP 800-207.
  • Experience with HSM-backed roots of trust and enterprise ICAM integration.
  • Working knowledge of FIPS 203, 204, and 205 and their HSM implementation implications.
  • Demonstrated experience designing hybrid classical/PQC architectures or cryptographic modernization strategies.

WHAT SETS YOU APART

  • CISSP-ISSAP, SABSA, TOGAF, or comparable security/architecture credentials.
  • Experience with Federal ICAM/FICAM and PIV/CAC environments.
  • Experience with Microsoft ADCS and enterprise certificate services.
  • Experience designing PQC migration strategies for large enterprise environments., * You will be a key contributor to Iron Bow’s transformational shift in how we deliver value to both customers and employees.
  • You will have the pleasure of working with passionate professionals in a culture that fosters a workplace where everyone feels respected, supported and empowered to succeed.

About the company

Iron Bow Technologies is for people who believetrust is paramount,transformation is embraced, andthe future is here,because “What we do matters!”

We are a next generation solutions provider, delivering mission success across government, healthcare, and commercial industries. Iron Bow relies on ourpassionate people,long standing partnerships, andstrategic thinkingto solve your most critical challenges.

Whether we team with clients, colleagues, or partners, we put each other first. It’s The Iron Bow Way.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:49 min

Securing service invocation with zero-trust networking access

Marc Müller Marc Müller · World Congress 2025

2:10 min

Managing private key control through non-custodial wallets

Peter Busch · LIVE

49 sec

Achieving competitive pricing through proprietary PKI technology

Julien Jenoudet Julien Jenoudet

5:21 min

Protecting infrastructure with the shared responsibility model

Mustafa Toroman · World Congress 2023

1:55 min

Mitigating agent risks with zero trust networking

Oren Penso Oren Penso · World Congress 2026 Europe

Videos

See all

Related articles

See all